Vulnerability Details CVE-2009-0091
Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.567
EPSS Ranking 98.0%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2009-0091
-
cpe:2.3:a:microsoft:.net_framework:1.0
-
cpe:2.3:a:microsoft:.net_framework:1.1
-
cpe:2.3:a:microsoft:.net_framework:2.0
-
cpe:2.3:a:microsoft:.net_framework:3.5
-
cpe:2.3:o:microsoft:windows_2000:-
-
cpe:2.3:o:microsoft:windows_7:-
-
cpe:2.3:o:microsoft:windows_server_2003:-
-
cpe:2.3:o:microsoft:windows_server_2003:r2
-
cpe:2.3:o:microsoft:windows_server_2008:-
-
cpe:2.3:o:microsoft:windows_server_2008:r2
-
cpe:2.3:o:microsoft:windows_vista:-
-
cpe:2.3:o:microsoft:windows_xp:-
-
cpe:2.3:o:microsoft:windows_xp:unknown